OWASP ZAP

OWASP ZAP

OWASP
+
+

Related Products

  • Aikido Security
    148 Ratings
    Visit Website
  • Astra Pentest
    225 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • Carbide
    88 Ratings
    Visit Website
  • KrakenD
    71 Ratings
    Visit Website
  • Jscrambler
    38 Ratings
    Visit Website
  • Parasoft
    140 Ratings
    Visit Website
  • UTunnel VPN and ZTNA
    118 Ratings
    Visit Website
  • YouTestMe
    37 Ratings
    Visit Website
  • Proton Pass
    31,996 Ratings
    Visit Website

About

OWASP ZAP (Zed Attack Proxy) is a free, open-source penetration testing tool being maintained under the umbrella of the Open Web Application Security Project (OWASP). ZAP is designed specifically for testing web applications and is both flexible and extensible. At its core, ZAP is what is known as a “man-in-the-middle proxy.” It stands between the tester’s browser and the web application so that it can intercept and inspect messages sent between browser and web application, modify the contents if needed, and then forward those packets on to the destination. It can be used as a stand-alone application, and as a daemon process. ZAP provides functionality for a range of skill levels – from developers, to testers new to security testing, to security testing specialists. ZAP has versions for each major OS and Docker, so you are not tied to a single OS. Additional functionality is freely available from a variety of add-ons in the ZAP Marketplace, accessible from within the ZAP client.

About

Highest rated DAST solution by an independent research firm three years in a row. Automatically assess modern web apps and APIs with fewer false positives and missed vulnerabilities. Fast-track fixes with rich reporting and integrations, and inform compliance and development stakeholders. Effectively manage the security assessment of your application portfolio, regardless of its size. Automatically crawl and assess web applications to identify vulnerabilities like SQL Injection, XSS, and CSRF. The modern UI and intuitive workflows built on the Insight platform make InsightAppSec easy to deploy, manage, and run. Scan applications hosted on closed networks with the optional on-premise engine. InsightAppSec assesses and reports on your web app's compliance to PCI-DSS, HIPAA, OWASP Top Ten, and other regulatory requirements.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

A Security Testing application for DevOps teams or companies

Audience

Development teams interested in a Dynamic Application Security Testing (DAST) solution

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

$2000 per app per year
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

OWASP
Founded: 2001
United States
www.zaproxy.org

Company Information

Rapid7
Founded: 2000
United States
www.rapid7.com/products/insightappsec/

Alternatives

Caido

Caido

Caido Labs Inc.

Alternatives

Burp Suite

Burp Suite

PortSwigger
Invicti

Invicti

Invicti Security

Categories

Categories

Integrations

Azure Pipelines
Blink
Carbon Black EDR
Coalfire
CyberArk Privileged Access Manager
Do Status
Docker
FuzzDB
Hexway Pentest Suite
IriusRisk
Jenkins
Jira
Nucleus
Phoenix Security
Seconize DeRisk Center
Selenium IDE
Sn1per Professional
Subject7
VMware NSX

Integrations

Azure Pipelines
Blink
Carbon Black EDR
Coalfire
CyberArk Privileged Access Manager
Do Status
Docker
FuzzDB
Hexway Pentest Suite
IriusRisk
Jenkins
Jira
Nucleus
Phoenix Security
Seconize DeRisk Center
Selenium IDE
Sn1per Professional
Subject7
VMware NSX
Claim OWASP ZAP and update features and information
Claim OWASP ZAP and update features and information
Claim InsightAppSec and update features and information
Claim InsightAppSec and update features and information